The Peculium Model: Information Security Risk Management for the South African SMME.

Liesl van Niekerk, Les Labuschagne · 2006

Small, medium and micro enterprises (SMMEs) in South Africa contribute over 40% to the gross domestic product. However, these organisations have a failure rate of 80%, mostly due to a lack of management skills. SMMEs also do not aspire to corporate governance standards for these management skills due to the lack of awareness of corporate governance best practice as well as the non-enforced implementation of King II by SMMEs. Risk management, as a component of King II, is consequently also optional, thus creating a lack of enforced information security risk management. The Peculium Model has been created for the small business environment in South Africa, specifically for the analysis and management of information security risks. The model is based on a framework derived from the examination of the risk management component of King II, CobiT for control of risk management, OCTAVE for asset-based risk management, CRAMM for monitoring of risk mitigation and ISO 17799 for cyclical risk management. The composition of the model allows for SMMEs and also ensures a distinctive link between board-level management and the risk management team implementing the model. Nevertheless, the model is in a simplified format, allowing the layperson to achieve results. The model has been tested and validated using a case study. The Peculium Model includes best practices from endorsed international standards. It provides a solution that offers a heightened awareness of risk in the organisation through staff involvement and board-level governance of the entire process. This paper presents the route followed in creating the model, and the validation performed to demonstrate its value.

Read the paper · More papers on PaperTik